Opens in a new tab

Oktane26 Takeaways From a 13-Time Attendee: Why identity is becoming the control plane for the AI enterprise

  • Blog

Arun Shrestha

October 1, 2026

Oktane26 was my 13th Oktane.

I was at the first one, when fewer than 500 people gathered around a young company and a big idea that identity would become a foundational layer of the cloud. I’ve watched every Oktane since from a different seat; first as Okta’s VP of Customer Success, then as co-founder of BeyondID as it became Okta’s first Diamond Partner, and now as part of KeyData Cyber, where identity, cybersecurity, governance and AI are converging into a single conversation.

This year in Las Vegas, the feeling in the halls was unmistakable. The momentum is back.

Identity didn’t get commoditized. AI made it bigger.

For a while, people asked whether identity would get absorbed into cloud platforms and security stacks. AI is proving the opposite. Every agent, workload, API and autonomous process is a new identity that has to be discovered, authenticated, authorized, governed and monitored.

And the human behind it matters more, not less. When an agent takes an action, we still need to know which human authorized it, what authority was delegated, what it can reach, what it actually did, and who is accountable.

Those are identity questions. Okta’s answer at Oktane was to position its platform as an identity security fabric spanning humans, machines and AI agents, with Auth0 carrying the same idea into customer and B2B experiences.

What mattered most

Agents become first-class identities

Okta for AI Agents now covers the full agent lifecycle: discover it, control its connections, watch what it does and shut it down. Agent SSO, Agent-to-Agent Connections and Resource Access Certifications are available today. Agent Gateway, which sits between an agent and every tool it calls, enforcing policy and logging each interaction rolls out next, followed by a runtime kill switch that can revoke every active token an agent holds, all targeted before the end of 2026.

The end of the API-key Wild West

Agent SSO brings Cross App Access to Okta’s SSO customers, replacing long-lived keys with short-lived, identity-governed tokens. Picture the future enterprise as Human → Agent → Agent → Application → API → Data. Every hop is a trust boundary, and identity has to travel with the transaction.

Governing agents, wherever your users live

Okta will now govern agents even when the human identity sits in another identity provider. That is the reality of every global enterprise I work with; Okta here, Entra there, acquired directories everywhere. Securing AI can’t wait for consolidation. Interoperability and open standards are the whole game.

Governance goes continuous

Automated Drift Detection & Remediation in Okta Identity Governance (early access targeted for Q4 2026) catches and revokes access that drifts from policy. Okta Privileged Access extends zero standing privilege to network devices, pipelines, workloads and agents (GA targeted for Q1 2027). And Permiso, which Okta closed on in August, brings threat detection across identity providers, clouds and SaaS.

Put together, that’s the real story. Authentication asks who you are. Authorization asks what you can do. Governance asks whether you should still be able to do it. Threat detection asks whether what you’re doing right now matches the trust we granted. In an agentic world, all four have to run continuously and together.

Customer identity goes agentic, too

Imagine telling an agent: “Find me the best flight, use my loyalty status, stay within travel policy and book it.” The merchant now has to establish whose agent this is, whether the customer authorized it, what it can buy and what it can be told. Auth0’s new commerce and B2B capabilities point at this shift, from authenticating a person at a login page to establishing delegated trust in an autonomous transaction.

Okta also formed the Blueprint Alliance with AWS, CrowdStrike, Databricks, Google Cloud, Salesforce, ServiceNow, Zscaler and others, turning the Blueprint for the Secure Agentic Enterprise, it first published in March into an open, multi-vendor reference architecture. It rests on four questions: Where are my agents? What can they do? What are they doing? How do I respond?

No single vendor will secure the agentic enterprise, and one gap is worth evaluating, the frontier-model makers aren’t members yet. An architecture like this is only as strong as its coverage of where agents actually run.

Responsible AI is an identity problem

Every board is talking about responsible AI: model governance, privacy, bias, safety, human oversight. All necessary. But you can’t govern an autonomous system if you can’t say who owns it, whose authority it’s using, what credentials it holds and what it did.

When Hugging Face disclosed in 2024 that some Spaces secrets may have been accessed, its response was to revoke tokens and move users to fine-grained access tokens. The lesson here is that credentials and least privilege matter far more when software can act on its own. A compromised human credential is dangerous, but a compromised autonomous identity operating across dozens of systems has a very different blast radius.

Where BeyondID and Okta go next

I helped customers adopt Okta from inside Okta. We built BeyondID because turning identity strategy into production takes deep expertise and today, as an Okta Apex Partner, a multiple-time AMER Partner of the Year and one of a small number of globally authorized Auth0 delivery partners, that is still the work.

Okta’s own leadership put it plainly: “Identity is the control plane for AI.” I agree. But the question clients bring us has changed. It used to be “How do we deploy Okta?” Now it’s “How do we build a secure, governed and responsible AI enterprise?” Our job is to turn what was announced at Oktane into production architecture:

  • Discovering and governing human, machine and AI identities in one inventory
  • Establishing trusted delegation between people and the agents acting for them
  • Designing authorization for agents calling SaaS apps, APIs and MCP servers
  • Implementing least privilege and zero standing privilege for agents and workloads
  • Connecting governance to threat detection and response

That work is already in production.

“At Boston Medical Center, we partnered with Okta to deliver Epic-integrated identity; the kind of complex, regulated environment where the stakes for getting identity right are highest.”

Thirteen Oktanes in

Directories to federation. Passwords to passwordless. On-prem to cloud. Perimeter to Zero Trust. Access management to identity security. And now, human identity to human, machine and agent identity.

AI doesn’t replace the fundamentals. It raises the stakes on them: establish trust, authorize explicitly, apply least privilege, govern continuously, detect the abnormal, respond immediately.

The Identity Economy isn’t striking back because we’re returning to the IAM market of ten years ago. It’s striking back because the definition of identity is expanding. Every employee, customer, workload and machine has an identity. Now every AI agent needs one too and someone has to establish trust across billions of those interactions, decide what’s authorized, and shut it down when trust is broken.

That’s identity. After 13 Oktanes, I’m more convinced than ever that it has never mattered more.



Where are your agents? What can they reach? What can they do? How do I respond?

If you can’t answer those three questions today, start with a complimentary BeyondID AI Agent Discovery Workshop. In one week, we’ll inventory your agents, map their connections and deliver a governance roadmap built on Okta.

Case Studies

How a Global Law Firm Built an Identity Maturity Roadmap Through an Okta Tenant Health Check

A global law firm partnered with us to perform a comprehensive Okta Tenant Health Check and Rapid IAM Assessment. By diving deep into stakeholder workshops, process reviews, platform analysis, and risk assessments, the joint engagement successfully pulled back the curtain on the organization’s true identity posture, paving the way for a clear, strategic roadmap for future improvements.

  • Legal Services

Leading University Modernizes Student Identity Management with BeyondID’s Workday SIS Connector

A leading higher education institution partnered with BeyondID to modernize identity management by integrating Workday SIS and Okta.

  • Higher Education

Securing a Credit Union’s Digital Transformation with Okta and Auth0

This case study explores how one leading credit union partnered with us to modernize its digital infrastructure with Okta and Auth0 to deliver seamless, secure experiences across every channel, without losing what made it great.

  • Financial Services

Modernizing Digital Banking Access with BeyondID’s Application Integration Gateway

This case study looks at a recurring banking client that partnered with us to connect legacy infrastructure to a modern Okta-based identity environment.

  • Financial Services

Solving Legacy Identity Integration for a Large Automotive Enterprise

This case study looks at a large automotive enterprise that partnered with BeyondID – A KeyData Cyber Company to modernize workforce identity and create a scalable path for secure access across distributed operations.

  • Automotive

Securing AI Innovation for a Packaging Distributor

This case study looks at how BeyondID – a KeyData Cyber company helped an industrial packaging manufacturer securely adopt AI by modernizing its workforce identity environment, establishing governance for AI agents, and implementing identity controls to support secure, scalable AI innovation.

  • Manufacturing

Strengthening Security and Governance for a Healthcare Technology Platform Through an Okta Tenant Health Check

This case study looks at how BeyondID – a KeyData Cyber company conducted an Okta Tenant Health Check for a healthcare technology organization to assess the health of its production Okta environment, identify security and governance gaps, and provide a structured remediation roadmap aligned to the customer’s broader identity initiatives.

  • Healthcare

Unifying the Shopper Identity Across a Multi-Brand Global Retail Portfolio

This case study looks at a large global retailer with a portfolio of iconic lifestyle brands that undertook a Customer Identity and Access Management (CIAM) transformation powered by Okta to create a unified customer experience layer across all brands.

  • Retail

Migrating Echo Global Logistics’ Portfolio from OneLogin to Okta to Improve Security

Echo Global Logistics needed a robust identity solution to upgrade its security posture and enhance its environment.

  • Transportation

Genesys: Accelerating Identity Modernization with Okta for Secure Customer Experiences 

To modernize identity across its vast and complex IT landscape, Genesys partnered with Okta and BeyondID for a strategic, phased transformation.

  • Technology
See More

Need help getting started?

Get a clear view of your identity security posture
GET IN TOUCH
floating ice
SAP

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your customers.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

SAP

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable customer identity for modern applications

BeyondID connects SAP environments with the systems and applications organizations rely on every day. Our Connectors simplify integration between SAP and your broader identity ecosystem, enabling seamless access, automated identity processes, and stronger governance across the enterprise.

What this connector enables

Provisioning & De-Provisioning

Implementation Support

Compliance Assurance

Workday

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your students, faculty, and staff

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Workday Student SIS

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for Education

BeyondID’s Workday SIS–Okta Connector is a pre-built integration accelerator designed to automate the student identity lifecycle, from enrollment through graduation. Built on SCIM 2.0, it simplifies provisioning, reduces manual processes, and closes security gaps.

What this connector enables

Academic Data Enrichment

Automated Full & Incremental Sync

Academic Unit Filtering

Okta

AUTHORIZED PARTNER

Identity Security

Modern Identity experiences to secure every identity, everywhere.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

OKTA

IDENTITY & ACCESS MANAGEMENT (IAM)

Secure every identity across your organization

BeyondID brings award-winning Okta expertise to help organizations get more from their identity investment. As an Okta Apex Partner and multi-year Partner of the Year, we combine certified expertise, proven architecture, and proprietary solutions to solve complex identity challenges.

What We Deliver with Okta

Identity Security for All Identities

Managed Identity Services

Identity Modernization & Optimization

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your organization

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Application Integration Gateway (AIG)

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for modern applications

Modernize identity without disrupting the systems your business depends on. BeyondID’s Application Integration Gateway (AIG) connects legacy and modern environments to simplify migrations, unify identity data, and accelerate time to value.

What this connector enables

Seamless Migration

Virtual Directory

Unified Profile

Epic

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for Healthcare

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

EPIC

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for Healthcare

BeyondID’s Epic–Okta Provisioning Connector automates workforce identity management between Okta and Epic, streamlining account provisioning, updates, and deactivation while syncing identity changes across connected systems.

 

What this connector enables

Provisioning

User Sync

 Support

AWS

AUTHORIZED PARTNER

Workforce Identity

Modern Identity experiences for your organization

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

AWS

WORKFORCE IDENTITY & ACCESS MANAGEMENT (WIAM)

Secure, scalable workforce identity for modern applications

BeyondID Professional Services Units provide flexible, on-demand access to certified identity experts. From strategy to optimization and ongoing support, prepaid consulting hours help organizations get more from their Okta and Auth0 investments.

What this connector enables

Secure authentication for web and mobile applications

Customizable login and identity flows

Centralized workforce identity management

AUTHORIZED PARTNER

Customer Identity

Modern Identity experiences for your customers.

Secure by Design

Built with security, privacy and compliance in mind.

Global Scale

Trusted by thounsands of organizations worldwide.

Auth0

CUSTOMER IDENTITY & ACCESS MANAGEMENT (CIAM)

Secure, scalable customer identity for modern applications

BeyondID helps organizations design, implement, and optimize Auth0 to deliver secure authentication, seamless user experiences, and enterprise-grade scalability. From greenfield deployments to complex migrations, we ensure your CIAM platform is built to grow with your business.

What this connector enables

Secure authentication for web and mobile applications

Customizable login and identity flows

Centralized customer identity management

Search the Site